CVE-2018-17156 Information

Description

In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5 due to incorrectly accounting for padding on 64-bit platforms a buffer underwrite could occur when constructing an ICMP reply packet when using a non-standard value for the net.inet.icmp.quotelen sysctl.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

http://www.securityfocus.com/bid/106052 https://security.freebsd.org/advisories/FreeBSD-EN-18:13.icmp.asc

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.9

Share on: